Command Injection Vulnerability in TOTOLINK Router
CVE-2023-29800
9.8CRITICAL
What is CVE-2023-29800?
The TOTOLINK X18 firmware version V9.1.0cu.2024_B20220329 has a command injection flaw that allows attackers to exploit the UploadFirmwareFile function through the FileName parameter. This vulnerability can enable unauthorized command execution, posing significant security risks to affected devices.